All posts

CMS-0057 Checklist: What Health Systems Should Do Now to Prepare for the 2027 API Deadline

Blog

August 24, 2026

All posts

CMS-0057 Checklist: What Health Systems Should Do Now to Prepare for the 2027 API Deadline

Prior Authorization

Policy

Provider

August 24, 2026

Dive deeper into this article with AI

CMS-0057-F requires Medicare Advantage, Medicaid, CHIP, and Qualified Health Plan payers to implement FHIR-based prior authorization APIs by January 1, 2027. Health systems don't have a direct compliance obligation under the rule itself, but the organizations that treat this window as a passive wait-and-see period are going to fall behind the ones actively preparing their payer relationships, EHR readiness, and MIPS attestation strategy right now.

This checklist breaks down what that preparation actually looks like, organized around the questions revenue cycle, patient access, and IT leaders are asking as the deadline approaches.

What Is CMS-0057-F, in Practical Terms?

CMS-0057-F, the CMS Interoperability and Prior Authorization Final Rule, is a federal regulation that requires impacted payers to build standardized, FHIR-based APIs for prior authorization submission, tracking, and decisioning. Operational requirements, including 72-hour urgent and 7-day standard decision timeframes and specific denial reasoning, took effect January 1, 2026. The remaining piece, full API implementation across Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs, is due January 1, 2027.

For a deeper breakdown of how this rule fits into the broader prior authorization regulatory landscape, see our Regulation & Compliance guide.

Why This Isn't Just a Payer-Side Issue

The rule's compliance obligation sits with payers, not health systems, but the operational impact doesn't stop there. Once payers stand up FHIR APIs, the health systems positioned to actually use that connectivity, rather than continuing to submit and track authorizations the way they did historically, are the ones who convert this regulatory shift into faster turnaround, fewer denials, and less manual staff time.

There's a compliance-adjacent incentive layered on top of that operational case, too. CMS has tied a new MIPS Promoting Interoperability measure to Prior Authorization API use, originally set as mandatory beginning with the 2027 performance year. A pending CY 2027 Physician Fee Schedule proposal would push that mandatory status to 2028, but that change isn't finalized, so the infrastructure work either way lands on the same timeline. The ones who aren't ready simply keep working the old way alongside a payer infrastructure that's evolved past them. That gap is the real planning problem, and it's solvable well ahead of the deadline.

The CMS-0057 Readiness Checklist for Health Systems

1. Assess your payer landscape now

Not every payer will be equally ready by January 1, 2027, and connectivity will roll out unevenly across national, regional, and delegated entities. Start by mapping which of your health plans are subject to CMS-0057-F, and which are likely to be early movers on API availability versus later adopters.

2. Confirm internal planning and stakeholder ownership

Prior authorization technology sits at the intersection of IT, revenue cycle, patient access, and compliance. Before technical implementation starts, confirm who owns this internally and whether a formal planning process, including a stakeholder list and a defined scope, is already underway.

3. Validate API scope with your prior authorization vendor

Not all payer APIs will support the same lines of business, services, or submission capabilities at launch. Ask your vendor how they're validating and prioritizing payer connections, and whether your existing submission workflows (278 transactions, portal, eFax) will continue functioning as a fallback while API coverage expands.

4. Plan your MIPS Promoting Interoperability attestation strategy

Beginning with the 2027 performance year, eligible providers must annually attest under MIPS Promoting Interoperability that they used electronic prior authorization via a qualifying Prior Authorization API during the reporting period, or qualify for an exclusion. Decide now whether attestation will happen at the health system or individual physician level, since that decision affects how data needs to be tracked and reported internally.

5. Choose a technology partner built for this transition, not retrofitted for it

FHIR-native architecture and Da Vinci implementation guide support are either foundational to how a solution was built or they're not. A vendor managing payer-side API connectivity on your behalf, while your existing EHR workflows continue functioning without disruption, removes the burden of building and maintaining individual FHIR connections payer by payer.

Frequently Asked Questions

Does CMS-0057-F require health systems to build anything? No. The compliance obligation under CMS-0057-F sits with impacted payers, who must build the required FHIR APIs. Health systems don't have a direct build requirement, but they do need a strategy for connecting to and using that new payer infrastructure as it comes online, ideally through a prior authorization vendor that manages the API connectivity layer.

What's the difference between CMS-0057-F and MIPS electronic prior authorization requirements? CMS-0057-F is the interoperability rule that requires payers to build FHIR-based APIs. MIPS Promoting Interoperability is a separate CMS incentive program under which eligible providers must attest, beginning with the 2027 performance year, that they used electronic prior authorization through a qualifying API. The two are connected but distinct: one is a payer build requirement, the other is a provider reporting requirement.

When is the CMS-0057-F API deadline? Impacted payers must have Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs operational by January 1, 2027. Operational requirements around decision timeframes and denial specificity took effect earlier, on January 1, 2026.

What happens if a health system isn't ready when payer APIs go live? There's no direct penalty for health systems under CMS-0057-F itself. The cost is operational rather than regulatory: organizations without a plan for using the new API infrastructure continue relying on slower, more manual submission and tracking methods while their payers' capabilities move forward without them, and they risk missing the readiness needed for 2027 MIPS attestation.

The Bottom Line

CMS-0057-F puts the build requirement on payers, but the advantage goes to the health systems that show up ready. Mapping your payer landscape, aligning internal stakeholders, working through EHR-specific readiness steps, and settling your MIPS attestation approach now, rather than in Q4 2026, is what separates organizations that experience this transition smoothly from those that scramble to catch up.

For help preparing your workflow for regulatory changes, contact us.